[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcKlETx1Djuiu5QKAyyJg67AkUu2WsyIHACG1mOVU-ws":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},701,"How can I delete EVT log records for a specific time period on a Windows XP system?","You can use either DLL injection or the DuplicateHandle method to obtain a handle to the EVT log file, then map it into memory via CreateFileMapping and MapViewOfFile, and overwrite the targeted records. On XP, first enumerate handles using NtQuerySystemInformation with SystemExtendedHandleInformation (type 0x1c for file handles), filter for log file handles with GrantedAccess = 0x0012019f, and then apply the chosen technique. For full implementation, refer to the [Windows Event Viewer Log (EVT) Single Log Deletion (Part 3)](\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system) article and the linked [Part 2](\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files) for the core deletion logic.","\u003Cp>You can use either DLL injection or the DuplicateHandle method to obtain a handle to the EVT log file, then map it into memory via CreateFileMapping and MapViewOfFile, and overwrite the targeted records. On XP, first enumerate handles using NtQuerySystemInformation with SystemExtendedHandleInformation (type 0x1c for file handles), filter for log file handles with GrantedAccess = 0x0012019f, and then apply the chosen technique. For full implementation, refer to the [Windows Event Viewer Log (EVT) Single Log Deletion (Part 3)](\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system) article and the linked [Part 2](\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files) for the core deletion logic.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-delete-evt-log-records-for-a-specific-time-period-on-a-windows-xp-syst-1777482263213","EVT log deletion, Windows XP, handle enumeration, DLL injection, DuplicateHandle, file mapping, CreateFileMapping, MapViewOfFile",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},174,"Windows Event Viewer Log (EVT) Single Log Deletion (Part 3) — Deleting EVT Log Records for a Specified Time Period on the Current System","windows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system","Learn to delete Windows EVT log records for a specific time period on XP systems via handle enumeration and DLL injection methods. Includes code examples.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The third article in the series on Windows Event Viewer Log (EVT) single log deletion introduces methods and detailed testing procedures for deleting EVT log records for a specified time period on the current system, explains the reasons why the number of logs cannot be modified, and finally provides open-source implementation code for querying and modifying log content.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method for enumerating all system handles on Windows XP\u003C\u002Fli>\u003Cli>Criteria for filtering log file handles\u003C\u002Fli>\u003Cli>Example code for DLL injection on Windows XP\u003C\u002Fli>\u003Cli>Actual testing process\u003C\u002Fli>\u003Cli>Reasons why the number of logs cannot be modified\u003C\u002Fli>\u003Cli>Implementation details of the log query program\u003C\u002Fli>\u003Cli>Implementation details of the log modification program\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Enumerating System Handles on Windows XP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Windows Single Log Deletion (5) – Deleting Current System Single Log Records by Obtaining Log File Handles via DuplicateHandle\" introduced the implementation method for Windows 8 and later systems:\u003C\u002Fp>\u003Col>\u003Cli>Using NtQuerySystemInformation to query SystemHandleInformation can obtain handle information for all processes\u003C\u002Fli>\u003Cli>Obtaining handle names and specific numerical information via NtDuplicateObject\u003C\u002Fli>\u003Cli>Filtering out the desired handles\u003C\u002Fli>\u003Cli>Duplicating handles via DuplicateHandle\u003C\u002Fli>\u003Cli>Obtaining permission to modify log files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>On Windows XP systems, NtQuerySystemInformation cannot be used to query SystemHandleInformation to obtain process handle information\u003C\u002Fp>\u003Cp>Referring to Process Hacker's source code to find implementation methods\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fprocesshacker\u002Fprocesshacker\u002Fblob\u002Fe2d793289dede80f6e3bda26d6478dc58b20b7f8\u002FProcessHacker\u002Fhndlprv.c#L307\u003C\u002Fp>\u003Cp>Obtained reference materials:\u003C\u002Fp>\u003Cp>On Windows 8 and later, NtQueryInformationProcess with ProcessHandleInformation is the most efficient method.\u003C\u002Fp>\u003Cp>On Windows XP and later, NtQuerySystemInformation with SystemExtendedHandleInformation.\u003C\u002Fp>\u003Cp>Otherwise, NtQuerySystemInformation with SystemHandleInformation can be used.\u003C\u002Fp>\u003Cp>Attempt the second method: query SystemExtendedHandleInformation using NtQuerySystemInformation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The second method supports Windows XP and later systems\u003C\u002Fp>\u003Ch2>0x03 Filter handles for specified log files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Filter handles of type file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ObjectTypeNumber = 0x1c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For Windows 8 and later systems, ObjectTypeNumber = 0x1e\u003C\u002Fp>\u003Cp>For Windows XP and Windows 7 systems, ObjectTypeNumber = 0x1c\u003C\u002Fp>\u003Ch3>2. Filter out handles that may cause hangs\u003C\u002Fh3>\u003Cp>Determine via the WaitForSingleObject API\u003C\u002Fp>\u003Cp>Otherwise, it will cause the process to hang\u003C\u002Fp>\u003Ch3>3. Narrow down the scope by specifying file attributes\u003C\u002Fh3>\u003Cp>Log file attributes are fixed: handle-&gt;GrantedAccess = 0x0012019f\u003C\u002Fp>\u003Cp>The complete implementation code has been open-sourced, download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code implements searching based on input keywords to obtain corresponding handle names and Handle values\u003C\u002Fp>\u003Ch2>0x04 Log Deletion Implementation Method 1: Obtaining Handle Operation Permissions via DLL Injection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Inject a DLL into the system process, the DLL file can then obtain the handle to the log file\u003C\u002Fp>\u003Cp>The subsequent operations are:\u003C\u002Fp>\u003Col>\u003Cli>Call the function CreateFileMapping() to create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify the data in memory to delete specified log records\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write the memory data to disk\u003C\u002Fli>\u003Cli>Clear the memory mapping object\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For the complete implementation process, refer to the previously introduced article on deleting single evtx file logs: 'Windows XML Event Log (EVTX) Single Log Deletion (Part 4) – Deleting Current System Single Log Records by Injecting to Obtain Log File Handle'\u003C\u002Fp>\u003Cp>Under the XP system, the method of NtCreateThreadEx + LdrLoadDll cannot be used to inject DLL; you can directly call CreateRemoteThread\u003C\u002Fp>\u003Cp>Implementation code can be referenced:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Log Deletion Method 2: Obtaining Handle Operation Permissions via DuplicateHandle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the previous article \"Windows XML Event Log (EVTX) Single Log Deletion (5) – Deleting a Single Log Record from the Current System by Obtaining Log File Handle via DuplicateHandle\"\u003C\u002Fp>\u003Cp>After filtering the handles, call NtDuplicateObject again to obtain the real handle and perform deletion operations on the log file\u003C\u002Fp>\u003Cp>Similarly, the following operations are required:\u003C\u002Fp>\u003Col>\u003Cli>Call the CreateFileMapping() function to create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the MapViewOfFile() function to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify the data in memory to delete the specified log record\u003C\u002Fli>\u003Cli>Call the FlushViewOfFile() function to write the memory data to disk\u003C\u002Fli>\u003Cli>Clear the memory mapping object\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For the log deletion part, refer to the previous article \"Windows Event Viewer Log (EVT) Single Log Deletion (2) – Program Implementation to Delete Log Records within a Specified Timeframe from an EVT File\"\u003C\u002Fp>\u003Cp>Here is a complete implementation code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements the deletion of multiple log records within a specified timeframe from a given EVT file and generates debug files sys2.evt and sys3.evt\u003C\u002Fp>\u003Cp>sys2.evt saves the array content after log deletion\u003C\u002Fp>\u003Cp>sys3.evt saves the content mapped into memory\u003C\u002Fp>\u003Cp>After program execution, sys2.evt and sys3.evt successfully deleted the specified logs, but the current system's log file generated errors\u003C\u002Fp>\u003Cp>For comparative testing, I adjusted the deletion time period to values outside the current logs, meaning no logs would be deleted. After program execution, the current system's log file remained normal\u003C\u002Fp>\u003Cp>Furthermore, as long as the number of logs is not changed, modifying the log content keeps the current system's log file normal\u003C\u002Fp>\u003Cp>This leads to a conclusion:\u003Cstrong>It is impossible to change the number of logs by obtaining the log file handle and modifying memory data\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similarly, directly modifying the File header of the memory file through ProcessHacker also cannot change the number of logs\u003C\u002Fp>\u003Cp>Wrote a program to verify, using the API GetNumberOfEventLogRecords to query the number of logs\u003C\u002Fp>\u003Cp>C code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#pragma comment(lib,\"Advapi32.lib\")\u003Cbr>\u003Cbr>int main(int argc, char *argv[])\u003Cbr>{\u003Cbr>\tHANDLE hEventLog = NULL;\u003Cbr>\u003Cbr>\thEventLog = OpenEventLog(NULL, argv[1]);\u003Cbr>\tif (NULL == hEventLog)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"OpenEventLog failed with 0x%x.\\n\", GetLastError());\u003Cbr>\t\tgoto cleanup;\u003Cbr>\t}\u003Cbr>\u003Cbr>\tDWORD NumberOfRecords = 0;\u003Cbr>\tBOOL flag = GetNumberOfEventLogRecords(hEventLog, &amp;NumberOfRecords);\u003Cbr>\u003Cbr>\tif (NULL == flag)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"GetNumberOfEventLogRecords failed with 0x%x.\\n\", GetLastError());\u003Cbr>\t\tgoto cleanup;\u003Cbr>\t}\u003Cbr>\tprintf(\"%d\\n\", NumberOfRecords);\u003Cbr>\u003Cbr>cleanup:\u003Cbr>\u003Cbr>\tif (hEventLog)\u003Cbr>\t\tCloseEventLog(hEventLog);\u003Cbr>\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd：\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>GetNumberOfEventLogRecords.exe system\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Get the number of log records\u003C\u002Fp>\u003Cp>Directly modify the Last (newest) record number in the File header and the Last (newest) record number in the End of file record of the memory file via ProcessHacker\u003C\u002Fp>\u003Cp>Execute the program again to obtain the number of log records, and find that the obtained number of log records remains unchanged\u003C\u002Fp>\u003Cp>Verify the conclusion: modifying log content in memory cannot change the actual number of log records\u003C\u002Fp>\u003Ch2>0x06 Program Implementation Details for Log Query and Log Modification\u003C\u002Fh2>\u003Cp>The code for log query is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements traversing logs and displaying information for each log\u003C\u002Fp>\u003Cp>The code for log modification is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements modifying information of specified logs\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two methods for deleting evt log records within a specified time period in the current system: obtaining handle operation permissions through DLL injection and DuplicateHandle respectively, and utilizing these handles to modify log files\u003C\u002Fp>\u003Cp>The deletion method is not simple overwriting but complete removal of logs from a certain period. Evtx file log deletion can also refer to this approach, though implementation is relatively more complex. Implementation code for evtx will be updated subsequently\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",6,"published","2026-02-02T07:38:21.203Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Delete Windows EVT Logs by Time Period: XP Handle Enumeration & Injection","Windows XP, EVT log deletion, event viewer, handle enumeration, DLL injection, log forensics, system security",false,[],{"docs":41,"hasNextPage":38},[42,43,44,45,4],705,704,703,702,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.243Z","2026-07-23T16:01:59.181Z","draft","2026-07-23T16:14:16.013Z"]